exam questions

Exam SY0-701 All Questions

View all questions & answers for the SY0-701 exam

Exam SY0-701 topic 1 question 11 discussion

Actual exam question from CompTIA's SY0-701
Question #: 11
Topic #: 1
[All SY0-701 Questions]

Several employees received a fraudulent text message from someone claiming to be the Chief Executive Officer (CEO). The message stated:
“I’m in an airport right now with no access to email. I need you to buy gift cards for employee recognition awards. Please send the gift cards to following email address.”
Which of the following are the best responses to this situation? (Choose two).

  • A. Cancel current employee recognition gift cards.
  • B. Add a smishing exercise to the annual company training.
  • C. Issue a general email warning to the company.
  • D. Have the CEO change phone numbers.
  • E. Conduct a forensic investigation on the CEO’s phone.
  • F. Implement mobile device management.
Show Suggested Answer Hide Answer
Suggested Answer: BC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mehsotopes
Highly Voted 11 months, 1 week ago
Selected Answer: BC
It is already known that the message is not being sent from the CEO, & awareness of this attack should be known among the company by using the proper training to identify when an attacker is smishing using employee likeness. It is not known if devices are compromised, but if employees are aware of the situation, then that can be figured out as well.
upvoted 12 times
...
AbdullahMohammad251
Highly Voted 6 months, 1 week ago
Selected Answer: BC
A fraudulent message was sent without spoofing the sender's number, indicating the message did not come from a legitimate source and the phone wasn't stolen. Therefore, we don't need to change numbers or conduct a forensic investigation on the CEO's phone. We will first inform the employees about the current smishing attack. Then, adjust the annual Company training to include awareness of and protection against similar smishing attacks.
upvoted 6 times
...
IT_dude_in_training
Most Recent 3 weeks, 2 days ago
Selected Answer: BC
B. Add a smishing exercise to the annual company training Smishing is a type of phishing attack via text messages. Incorporating it into annual company training will help employees recognize such fraudulent attempts and improve overall security awareness. C. Issue a general email warning to the company This will quickly alert all employees about the specific phishing attempt and provide guidance on how to handle such situations, reducing the risk of future incidents.
upvoted 1 times
...
JackExam2025
1 month, 3 weeks ago
Selected Answer: BC
The best responses are to train employees through a smishing exercise and alert the entire company through an email warning to prevent further attacks.
upvoted 1 times
...
habbeysax
3 months ago
Selected Answer: BC
A fraudulent message was sent without the sender's number being spoofed, confirming it did not originate from a legitimate source and that the phone has not been stolen. Consequently, there is no need to change numbers or conduct a forensic investigation on the CEO's phone. Our immediate action will be to inform employees about the ongoing smishing attack. Additionally, we will update the annual company training to include awareness and prevention of similar smishing attacks.
upvoted 1 times
...
JRCHENRY
3 months, 3 weeks ago
Selected Answer: BC
Proper training to identify smishing and Employee awareness.
upvoted 1 times
...
ProudFather
4 months, 1 week ago
Selected Answer: BC
BC seems to be the most reasonable options. As the company with need to be trained and made aware of such attacks so they do not fall victim to this in the future.
upvoted 1 times
...
famuza77
5 months, 4 weeks ago
Selected Answer: BF
How not implementing Mobile Device Management is gonna help on the situation? Technical measures are more importante than annual trainings? stop asking GTP for responses and think
upvoted 3 times
shootweb
3 weeks, 6 days ago
MDM is helpful in many cases, but this is a social engineering scenario where MDM falls short, whereas an email alert does not. When the specifics are unknown, we must opt for a broad and immediate countermeasure that mitigates risk almost instantly (C) rather than a specific technical control that takes time to implement and does not address the issue—social engineering (F). Thus, the answer is BC.
upvoted 1 times
...
TheeLotus
1 month, 3 weeks ago
This is correct in my opinion. You should have an immediate response to secure what has been breached. I feel like creating a training takes weeks to create and doesnt address the problem immediately
upvoted 1 times
...
...
dbrowndiver
6 months, 1 week ago
Selected Answer: BC
In this scenario, employees have received a fraudulent text message impersonating the CEO, aiming to trick them into purchasing and sending gift cards. The attack is a classic example of smishing, a type of phishing conducted through SMS Add a smishing exercise to the annual company training-Training employees through realistic exercises will prepare them for recognizing smishing attempts in the future. They will learn how to spot red flags in messages that seem urgent and authoritative but are suspicious in nature. Issue a general email warning to the company-o Alerting the organization helps contain the threat and reduces the chance of employees inadvertently engaging with the scam. It is an immediate response that mitigates risk by stopping the scam in its tracks.
upvoted 3 times
...
Segunmx
6 months, 2 weeks ago
Selected Answer: BC
These are the correct answers. General email warnings to the employees and there’s a need for more trainings.
upvoted 1 times
...
AbdullahMohammad251
9 months, 3 weeks ago
Selected Answer: BC
A fraudulent message was used, and the sender's number was not spoofed, meaning the message didn't come from a legitimate source. The question didn't mention the phone was stolen either. Therefore, we don't need to change numbers or conduct a forensic investigation on the CEO's phone. First, we will inform the employees about the current smishing attack. Then, we will adjust our annual company training to include protection against smishing attacks.
upvoted 2 times
...
hasquaati
11 months ago
Selected Answer: BC
BC, I eliminated the incorrect questions to this one.
upvoted 2 times
...
shady23
11 months, 1 week ago
Selected Answer: BC
B. Add a smishing exercise to the annual company training. C. Issue a general email warning to the company.
upvoted 2 times
...
Yoez
11 months, 1 week ago
Correct Answer: BC
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago